
[CIVN-2026-0387] Multiple Vulnerabilities in Mozilla Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Mozilla Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Mozilla Firefox versions prior to 153
Mozilla Firefox ESR versions prior to 115.38 and Firefox ESR versions prior to 140.13
Mozilla Thunderbird ESR versions prior to 140.13 and Thunderbird versions prior to 153
Overview
Multiple vulnerabilities have been reported in Mozilla products which could be exploited by a remote attacker to execute arbitrary code, obtain sensitive information, perform spoofing attacks, bypass security restrictions, escalate privileges, escape browser sandbox protections, or cause a Denial of Service (DoS) condition on the targeted system.
Target Audience:
Individuals and organizations using the affected products.
Risk Assessment:
High risk of unauthorized access to sensitive information.
Impact Assessment:
Potential for data theft, sensitive information disclosure and complete compromise of system.
Description
Mozilla Firefox is a free and open-source web browser developed by the Mozilla Foundation, while Firefox ESR (Extended Support Release) is a stable version designed for organizations requiring long-term support with security and maintenance updates. Mozilla Thunderbird is an open-source email client developed by the Mozilla Foundation.
Multiple vulnerabilities exist in the affected Mozilla products due to invalid pointer dereference, incorrect boundary conditions, integer overflow, information disclosure, memory safety flaws, use-after-free, sandbox escape, mitigation bypass, privilege escalation, same-origin policy bypass, and spoofing issues in various components including Audio/Video, JavaScript Engine, DOM, Networking, Graphics, Security, Widget, WebRTC, Enterprise Policies, Profile Backup, Form Autofill, Popup Blocker, Toolbar, Web Speech, WebExtensions, Application Update, and Accessibility APIs. A remote attacker could exploit these vulnerabilities by convincing a user to visit a specially crafted web page or process malicious web content.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, disclose sensitive information, perform spoofing attacks, bypass security restrictions, escalate privileges, or cause a Denial of Service (DoS) condition on the targeted system.
Solution
Apply appropriate updates as mentioned in:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-69/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/
Vendor Information
Mozilla
https://www.mozilla.org/en-US/security/advisories/
References
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-69/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-71/
https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/
CVE Name
CVE-2026-15718
CVE-2026-15719
CVE-2026-16349
CVE-2026-16350
CVE-2026-16362
CVE-2026-16351
CVE-2026-16352
CVE-2026-16363
CVE-2026-16353
CVE-2026-16354
CVE-2026-16368
CVE-2026-16369
CVE-2026-16355
CVE-2026-16356
CVE-2026-16357
CVE-2026-16371
CVE-2026-16374
CVE-2026-16375
CVE-2026-16377
CVE-2026-16379
CVE-2026-16358
CVE-2026-16381
CVE-2026-16383
CVE-2026-16387
CVE-2026-16390
CVE-2026-16391
CVE-2026-16359
CVE-2026-16396
CVE-2026-16405
CVE-2026-16412
CVE-2026-16360
CVE-2026-16361
CVE-2026-16364
CVE-2026-16365
CVE-2026-16366
CVE-2026-16367
CVE-2026-16370
CVE-2026-16372
CVE-2026-16373
CVE-2026-16376
CVE-2026-16378
CVE-2026-16380
CVE-2026-16382
CVE-2026-16384
CVE-2026-16385
CVE-2026-16386
CVE-2026-16388
CVE-2026-16389
CVE-2026-16392
CVE-2026-16393
CVE-2026-16394
CVE-2026-16395
CVE-2026-16397
CVE-2026-16398
CVE-2026-16399
CVE-2026-16400
CVE-2026-16401
CVE-2026-16402
CVE-2026-16403
CVE-2026-16404
CVE-2026-16406
CVE-2026-16407
CVE-2026-16408
CVE-2026-16409
CVE-2026-16410
CVE-2026-16411
CVE-2026-14899
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpzQ6UACgkQ3jCgcSdc
ys+SyA//QOkOdj5EByrc9TDIgdpDotWG90LtmW0L8DOjq2noU0ZYmygcuOhdGJdV
ARNpznJGTcfirxMuFDt6sTSSxDDXMagEjpE+4Mky13kLX7OiZGuxbAGJROb6INLU
iGDEQaTyg7q3dj9TUd4s4w6yjULjC2AIJD1uEcZAXruJGinR0r6JDIPW3GSXBUAR
uL1aOTkG16sukecwNy3B5dTBYNNTXIz1P9PP54hnrEIeWPY9lRhhqLo1EPRGAAX+
hy81tuDmtTCxQDtBU5eDrekOKBbcfbgbx8+UaXQPtxULLG6rr4LoH7eeUsaTGTTT
jyPi2ieGh9PU1OnpIisfFMWt27BY8+Pv+emCp/IITNEJFLPV9wJ+TN45GC8J0+DL
DY3Cdh+mc/AV6z1mnIuNhvZV1fAWATlK3YWFZWURDg61cbOORBGRjSvSxehPmq4d
ytP5+ZR9SMRNfXlaGzJ9YnjWnSq0RKG6JGW1c084XgUj0WBxo+WHc7Bg5W7yR6v6
TW+qc7hIobNXZfugC8YjMp16uWFGeX8/OmGu6hiK2MTsx28OV0gLQguaToATfWO1
k9L4trNtukMpcy7cqzkZhgBEmrm1TA6J9JapPiFu2w4yFMRMYaJGfEtmIDaGWr6B
Gy01nj6faIBeaRPoYcbUV+jDfI58T//oDfMaZwjjDjPw3XPt4Kk=
=ixBL
—–END PGP SIGNATURE—–


